All of lore.kernel.org
 help / color / mirror / Atom feed
From: Baolong Duan <blduan@linux.alibaba.com>
To: qemu-devel@nongnu.org
Cc: qemu-riscv@nongnu.org, alistair23@gmail.com,
	dbarboza@ventanamicro.com, cxx194832@alibaba-inc.com,
	zengxiangyi.zxy@alibaba-inc.com,
	Baolong Duan <blduan@linux.alibaba.com>
Subject: [RFC PATCH v1 01/17] docs/system/riscv/virt: document the cove-vm machine option
Date: Fri, 31 Jul 2026 11:49:55 +0800	[thread overview]
Message-ID: <20260731035011.4178103-2-blduan@linux.alibaba.com> (raw)
In-Reply-To: <20260731035011.4178103-1-blduan@linux.alibaba.com>

Describe the cove-vm option of the virt machine and how a CoVE TEE VM
(TVM) differs from a regular KVM guest: its memory and vCPU state are
owned by the TEE Security Manager (TSM), the guest images are measured
before it starts, interrupts are delivered as MSIs only, there is no
virtio-mmio transport and vhost cannot be used.

The option itself is added by the following patches.

Signed-off-by: Baolong Duan <blduan@linux.alibaba.com>
---
 docs/system/riscv/virt.rst | 39 ++++++++++++++++++++++++++++++++++++++
 1 file changed, 39 insertions(+)

diff --git a/docs/system/riscv/virt.rst b/docs/system/riscv/virt.rst
index 60850970ce..d053dbc300 100644
--- a/docs/system/riscv/virt.rst
+++ b/docs/system/riscv/virt.rst
@@ -146,6 +146,45 @@ The following machine-specific options are supported:
 
   Enables the riscv-iommu-sys platform device. Defaults to 'off'.
 
+- cove-vm=[on|off]
+
+  When this option is "on" the guest is created as a RISC-V CoVE
+  (Confidential VM Extension) TEE VM, or TVM. Defaults to "off". See
+  `Running a confidential VM`_ below.
+
+Running a confidential VM
+-------------------------
+
+With "cove-vm=on" the ``virt`` machine creates a TEE VM (TVM) instead of a
+regular KVM guest. The memory and the vCPU state of a TVM are owned by the
+TEE Security Manager (TSM) running in M-mode and are not accessible to the
+host, which changes the machine in a few ways:
+
+- the kernel, the initrd and the device tree are added to the initial
+  measurement of the guest before it starts, so that the guest can be
+  attested later on;
+
+- interrupts are delivered as MSIs only. An IMSIC is therefore mandatory and
+  "aia=aplic-imsic" is selected automatically when no AIA mode is requested.
+  The APLIC is emulated by QEMU because KVM does not implement one for a TVM;
+
+- no virtio-mmio transport is created. Devices have to be attached to the
+  PCIe host bridge, and they always negotiate VIRTIO_F_ACCESS_PLATFORM so
+  that DMA is bounced through memory the guest shares explicitly;
+
+- vhost cannot be used, as the kernel datapath has no access to guest memory.
+
+This requires a host with CoVE support, both in the firmware and in KVM, and
+it only works with ``-accel kvm``. An example command line is:
+
+.. code-block:: bash
+
+  $ qemu-system-riscv64 -M virt,cove-vm=on -accel kvm \
+      -m 256M -smp 1 -nographic \
+      -kernel Image -append "console=ttyS0 root=/dev/vda" \
+      -drive file=rootfs.ext4,format=raw,id=hd0,if=none \
+      -device virtio-blk-pci,drive=hd0,disable-legacy=on
+
 Running Linux kernel
 --------------------
 
-- 
2.34.1



  reply	other threads:[~2026-07-31  5:58 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-31  3:49 [RFC PATCH v1 00/17] target/riscv: Add KVM CoVE confidential VM support Baolong Duan
2026-07-31  3:49 ` Baolong Duan [this message]
2026-07-31  3:49 ` [RFC PATCH v1 02/17] hw/riscv/virt: add the cove-vm machine property Baolong Duan
2026-07-31  3:49 ` [RFC PATCH v1 03/17] target/riscv/kvm: create and measure a CoVE TEE VM Baolong Duan
2026-07-31  3:49 ` [RFC PATCH v1 04/17] accel/kvm: add kvm_gpa_to_userspace_addr() Baolong Duan
2026-07-31  3:49 ` [RFC PATCH v1 05/17] hw/riscv/boot: load and measure the images of a CoVE guest Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 06/17] hw/riscv/virt: measure the device tree " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 07/17] hw/riscv: adapt " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 08/17] hw/riscv/virt: use MSIs only for " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 09/17] hw/intc/riscv_aplic: emulate the APLIC " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 10/17] target/riscv/kvm: skip unsupported KVM requests " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 11/17] hw/virtio: force modern virtio " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 12/17] hw/net/virtio-net: do not use vhost " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 13/17] accel/kvm: only register the DRAM slot of " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 14/17] accel/kvm: skip MSI route updates for " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 15/17] accel/kvm: pin the vCPU threads of " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 16/17] accel/kvm: terminate on a system event " Baolong Duan
2026-07-31  3:50 ` [RFC PATCH v1 17/17] hw/core/machine-qmp-cmds: shut down a CoVE guest on reset Baolong Duan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260731035011.4178103-2-blduan@linux.alibaba.com \
    --to=blduan@linux.alibaba.com \
    --cc=alistair23@gmail.com \
    --cc=cxx194832@alibaba-inc.com \
    --cc=dbarboza@ventanamicro.com \
    --cc=qemu-devel@nongnu.org \
    --cc=qemu-riscv@nongnu.org \
    --cc=zengxiangyi.zxy@alibaba-inc.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.